Aller au contenu

Fiche vulnérabilité

CVE-2024-26739 : faille élevée debian debian linux (CVSS 7.8)

Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the skb, and haven't called tcf_mirred_forward(), yet, we need to tell the core to drop the skb by setting the retcode to SHOT. If we have called tcf_mirred_forward(), however, the skb is out of our hands and returning SHOT will lead to UaF. Move the retval override to the error path which actually need it.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
3 avr. 2024
Dernière mise à jour
4 août 2026

Produits concernés

  • debian debian linux
  • linux linux kernel

Références

Rechercher une autre vulnérabilité dans la base CVE